Page 3 - Table of Contents
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint VPN 38 Password 51 Status 53 DHCP 55 Log 57Help 59Advanced 60Filters 61 Forwarding 65 Dynamic Routing 70 Static Routing 71 DMZ Host 73 MAC Address Clone 75 DDNS 76 Appendix A: Troubleshooting 79 Common Problems and Solutions 79 Fr...
Page 4 - Chapter 1: Introduction; The Linksys EtherFast; Appendix F: Installing the TCP/IP Protocol
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 1 Chapter 1: Introduction The Linksys EtherFast ® Cable/DSL Router The Linksys Instant Broadband EtherFast Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint is the perfect solution for connecting a small groupof PCs to a h...
Page 5 - Dynamic IP Addresses
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 3 Instant Broadband ® Series 2 Dynamic IP Addresses A dynamic IP address is automatically assigned to a device on the network,such as PCs and print servers. These IP addresses are called “dynamic”because they are only temporarily ...
Page 6 - Chapter 2: Your Virtual Private; Network Setup Overview
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint Chapter 2: Your Virtual Private Network (VPN) Computer networking provides a flexibility not available when using an archa-ic, paper-based system. With this flexibility, however, comes an increased riskin security. This is why f i...
Page 7 - Firewall Router to Firewall Router; What is a Virtual Private Network?
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint There are two basic ways to create a VPN connection:• Firewall Router to Firewall Router • Computer (using VPN client software that supports IPSec) to FirewallRouter The Firewall Router creates a “tunnel” or channel between two en...
Page 8 - Chapter 3: Getting to Know the; WAN
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 9 Chapter 3: Getting to Know the EtherFast Cable/DSL Firewall Router The Router’s ports, shown in Figure 3-1, are where network cables are con-nected WAN The WAN (Wide Area Network) port is where you connectyour cable or DSL modem...
Page 9 - WAN and LAN LEDs; Proceed to “Chapter 4: Connect the Router.”; The Reset Button
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 11 Instant Broadband ® Series 10 WAN and LAN LEDs Link/Act Green. The Link/Act LED serves two purposes. If the LED is con-tinuously lit, the Router is successfully connected to a devicethrough the corresponding port (1, 2, 3 or 4/...
Page 10 - The Router’s hardware installation is now complete.; Chapter 4: Connect the Router; Overview; Connecting Your Hardware Together and Booting Up
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 13 Instant Broadband ® Series 12 Repeat the above step to connectmore PCs or network devices tothe Router. 3. Connect the Ethernet cable from your cable or DSL modem to the WAN port on the Router’sback panel, as shown in Figure 4-...
Page 11 - Chapter 5: Configure the PCs; Configuring Windows 95, 98, and Millennium PCs
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 1. Go to the Network screen by clicking the Start button. Click Settings and then Control Panel. From there, double-click the Network icon. 2. On the Conf iguration tab, shown in Figure 5-1, select the TCP/IP line for the applicab...
Page 12 - Click the OK button again. Windows may ask you for the original; Configuring Windows 2000 PCs
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 1. Go to the Network screen by clicking the Start button. Click Settings and then Control Panel. From there, double-click the Network and Dial-upConnections icon. 2. Select the Local Area Connection icon for the applicable Etherne...
Page 13 - Configuring Windows XP PCs
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint The following instructions assume you are running Windows XP with thedefault interface. If you are using the Classic interface (where the icons andmenus look like previous Windows versions), please follow the instructions forWindo...
Page 14 - Chapter 6: Configure the Router
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 21 Instant Broadband ® Series 3. Select Internet Protocol (TCP/IP), as shown in Figure 5-7, and click the Properties button. 4. Select Obtain an IP address automatically. Once the new window Select Obtain an IP address automatical...
Page 15 - Obtain an IP Address Automatically; A. S e l e c t O b t a i n a n I P; Static IP Address; A. Select Static IP as the WAN
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint Obtain an IP Address Automatically If your ISP says that you areconnecting through DHCP or adynamic IP address from yourISP, perform these steps: A. S e l e c t O b t a i n a n I P Automatically as the WANConnection Type. (Shown i...
Page 16 - PPTP; PPPoE; A. Select PPPoE as the WAN; RAS
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint PPTP PPTP is a service used in Europeonly. (Shown in Figure 6-8.) Ifyou are using a PPTP connec-tion, check with your ISP for thenecessary setup information. When you are f inished with theSetup tab, proceed to step 5. HBS HBS is ...
Page 17 - Router’s Web-based Utility; • Setup Enter the settings provided by your ISP.; Proceed to “Chapter 7: The Cable/DSL Firewall Router’s Web-based
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint Chapter 7: The Cable/DSL Firewall Router’s Web-based Utility For your convenience, use the Router’s web-based utility to administer it. Thischapter will explain all of the functions in this utility. The utility can beaccessed via ...
Page 18 - • Device IP Address and Subnet Mask The values for the Router’s IP; Router
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint • Device IP Address and Subnet Mask The values for the Router’s IP Address and Subnet Mask are shown here. The default values are192.168.1.1 for the Device IP Address and 255.255.255.0 for the SubnetMask. • WAN Connection Type The...
Page 19 - Static
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 31 Instant Broadband ® Series 30 PPPoE Some DSL-basedISPs use PPPoE( P o i n t - t o - P o i n tProtocol overEthernet) to establishInternet connectionsfor end-users. If youare connected to theInternet through aDSL line, check with...
Page 21 - HBS; Firewall
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 35 Instant Broadband ® Series HBS The HeartBeatSignal (HBS) is a service thatapplies to connec-tions in Australiaonly. (Shown inFigure 7-9.) Forusers in Australia,check with your ISPfor setup informa-tion. User Name and Password E...
Page 22 - • Cookie A cookie is data stored on your PC and used by Internet sites
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint PPTP Pass Through• Point-to-Point Tunneling Protocol Pass Through is the method used toenable VPN sessions to a Windows NT 4.0 or 2000 server. PPTP PassThrough is enabled by default. To disable this feature, click on Disable nextt...
Page 23 - Establishing a Tunnel; Then check the box next to Enable to enable the tunnel.; VPN
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint Virtual Private Networking (VPN) is a security measure that basically createsa secure connection between two remote locations. This connection is veryspecif ic as far as its settings are concerned; this is what creates the securit...
Page 24 - • IP Address - If you select IP Address, only the computer with the spe-; Local Secure Group and Remote Secure Group
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 41 40 • IP Address - If you select IP Address, only the computer with the spe- cif ic IP Address that you enter will be able to access the tunnel. In theexample shown in Figure 7-13, only the computer with IP Address192.168.1.10 c...
Page 25 - Remote Security Gateway; • Host - If you select Host for the Remote Secure Group, then the Remote
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 43 42 Remote Security Gateway The Remote Security Gateway is the VPN device, such as a second FirewallRouter, on the remote end of the VPN tunnel. Under Remote SecurityGateway, you have three options: IP Address, FQDN, and Any. • ...
Page 26 - Key Management; • Any - If you select Any for the Remote Security Gateway, as shown in
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint Key Management In order for any encryption to occur, the two ends of the tunnel must agree onthe type of encryption and the way the data will be decrypted. This is done bysharing a “key” to the encryption code. Under Key Managemen...
Page 28 - Advanced Settings for Selected IPSec Tunnel; Phase 1
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 49 48 EncryptionSelect the length of the key used to encrypt/decrypt ESP packets. There are twochoices: DES and 3DES. 3DES is recommended because it is more secure. AuthenticationSelect the method used to authenticate ESP packets....
Page 29 - Phase 2; Password
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 51 Phase 2 GroupThere are two Diff ie-Hellman Groups to choose from: 768-bit and 1024-bit.Diff ie-Hellman refers to a cryptographic technique that uses public and privatekeys for encryption and decryption. Key LifetimeIn the Key L...
Page 30 - Status
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 53 Do not restore the factory defaults unless you are having diff iculties with theRouter and have exhausted all other troubleshooting measures. Once the Routeris reset, you will have to re-enter all of your conf iguration data. U...
Page 31 - DHCP
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint From the DHCP screen, shown in Figure 7-28, you can conf igure the Router asa DHCP Server. A Dynamic Host Conf iguration Protocol (DHCP) server automatically assignsan IP address to each PC on your network for you. Unless you alre...
Page 32 - Log
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint The Log tab, shown in Figure 7-29, provides you with a log of all incoming andoutgoing URLs or IP addresses for your Internet connection. To access activity logs, select the Enable option next to Log. This function canbe disabled ...
Page 33 - • System Log The System Log screen displays a list of cold and warm; Help
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 59 From the drop-down menu, select the log you wish to view: All (to view alllogs), System Log, Access Log, Firewall Log, or VPN Log. • System Log The System Log screen displays a list of cold and warm starts, web login successes ...
Page 34 - Filters; Click Upgrade Firmware to display the window shown in Figure 7-32.; Advanced
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint The Filters screen, shown in Figure 7-33, allows you to block or allow specif ickinds of Internet usage. You can set up Internet access policies for specif ic PCs. Internet Access Policy Multiple f ilters can be saved as Internet ...
Page 35 - a. Click the Add Service; To see a summary of all Policies, click the Summary button.; Enter a Policy Name in the f ield provided.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 5. To block websites with specif ic URL addresses, enter each URL address in a Website Blocking by URL Address f ield. You can enter up to four URLaddresses. 6. To block websites that use specif ic keywords as part of their URL ad...
Page 36 - Forwarding; click the Modify button.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 65 From the Forwarding tab, shown in Figure 7-37, you can set up public serviceson your network, such as web servers, ftp servers, e-mail servers, or other spe-cialized Internet applications. (Specialized Internet applications are...
Page 37 - IP address of the server that you want the Internet users to be able; UPnP Forwarding
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 67 66 • Telnet A terminal emulation protocolcommonly used onInternet andTCP/IP-based net-works. It allows auser at a terminal orcomputer to logonto a remotedevice and run aprogram. • S M T P ( S i m p l e Mail TransferProtocol) Th...
Page 38 - Port Triggering
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 69 68 5. Enter the IP address of the server that you want the Internet users to be able to access. To f ind the IP address, go to “Appendix G: Finding the MACAddress and IP Address for Your Ethernet Adapter.” 6. Check the Enable b...
Page 39 - Static Routing; Dynamic Routing
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 71 70 If the Router is connected to more than one network, it may be necessary to setup a static route between them. This can be done from the Static Routingscreen, shown in Figure 7-41. A static route is a pre-determined pathway ...
Page 40 - DMZ Port
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 73 72 From the DMZ Host tab, shown in Figure 7-42, you can set Port 4/DMZ toDMZ or LAN connection. Any user on the Internet can access incoming or out-going data from the DMZ host without the use of f irewall protection. This fea-...
Page 41 - Current DMZ Host; MAC Address Clone
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 75 Specify an IP Address behind the DMZ Port: If you have multiple PCsconnected to Port 4/DMZ via a hub or switch, you can specify which PC isthe DMZ host. To expose a computer with a specif ic IP address, enter thatcomputer’s IP ...
Page 42 - DDNS
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint DynDNS.org To order DynDNS service, click the appropriate link at the top of the DDNSscreen. Username, Password, and Host Name Enter the Username, Password, andHost Name of the account you set up with DynDNS.org. Internet IP Addre...
Page 43 - Appendix A: Troubleshooting; E. Click the DNS tab, and make sure the DNS Enabled option is selected.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 79 Instant Broadband ® Series TZO.com To sign up for a free, 30-day trial of TZO service, order TZO service, or man-age your TZO service, click the appropriate link at the top of the DDNS screen. Domain Name, Email Address, and TZ...
Page 44 - adapter you are using, and select the Properties option.; • Right-click the Local Area Connection that is associated with the
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 81 Instant Broadband ® Series For Windows 2000: A. Click Start, Settings, and Control Panel. Double-click Network and Dial-Up Connections. B. Right-click the Local Area Connection that is associated with the Ethernet adapter you a...
Page 45 - Network Connections icon.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 83 Instant Broadband ® Series 82 C. In the command prompt, type ping 192.168.1.1 and press the Enter key. • If you get a reply, the computer is communicating with the Router.• If you do NOT get a reply, please check the cable, and...
Page 48 - G. Click the Apply and Continue buttons to continue.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 13. The firmware upgrade failed, and/or the Diag LED is flashing. The upgrade could have failed for a number of reasons. Follow these steps toupgrade the f irmware and/or make the Diag LED stop flashing: A. If the f irmware upgrad...
Page 50 - Network Address Translation
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 93 Instant Broadband ® Series 92 I set up an Unreal Tournament Server, but others on the LAN cannot join. What do I need to do? If you have a dedicated Unreal Tournament server running, you need to create a static IP for each of t...
Page 52 - Appendix B: Maximizing VPN
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 97 Instant Broadband ® Series 96 As secure as the Firewall Router makes your data, there are still more ways tomaximize security. The following are a few suggestions on how to increase datasecurity beyond the Firewall Router. 1) M...
Page 53 - Click the Finish button, making sure the Edit check box is checked.; Appendix C: Configuring IPSec; Introduction
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 99 Instant Broadband ® Series 98 1. Click the Start button, select Run, and type secpol.msc in the Open f ield. The Local Security Setting screen will appear as shown in Figure C-1. 2. Right-click IP Security Policies on Local Com...
Page 54 - Make sure the IP Filter
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 101 Instant Broadband ® Series 100 3. The IP Filter List screen should appear, as shown in Figure C-4. Enter an appropriate name, such as win->router, for the f ilter list, and de-select theUse Add Wizard check box. Then, click...
Page 55 - Use Add Wizard check box. Click the Add button.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 103 Instant Broadband ® Series 102 8. The IP Filter List screen should appear, as shown in Figure C-7. Enter an appropriate name, such as router->win for the f ilter list, and de-select the Use Add Wizard check box. Click the A...
Page 56 - Click the Filter Action
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 105 Instant Broadband ® Series 104 Tunnel 1: win->router 1. From the IP Filter List tab, shown in Figure C-10, click the f ilter listwin->router. 2. Click the Filter Action tab (as in Figure C-11),and click the f ilter actio...
Page 57 - but always
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 107 Instant Broadband ® Series 106 5. Change the authentica- tion method to Use thisstring to protect thekey exchange (pre-shared key), as shownin Figure C-14, andenter the preshared keystring, such asXYZ12345. Click theOK button....
Page 58 - Go to the IP Filter List
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 109 Instant Broadband ® Series 108 Tunnel 2: router->win 9. In the screen, shown in Figure C-18, make surethat “win -> router” isselect and deselect theUse Add Wizardcheck box. Then, clickthe Add button to cre-ate the second...
Page 59 - Click the Filter Action
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 111 Instant Broadband ® Series 110 13. Change the authenti- cation method to Usethis string to protectthe key exchange(preshared key), andenter the presharedkey string, such asXYZ12345, asshown in Figure C-22. (This is a samplekey...
Page 60 - Step Four: Assign New IPSec Policy
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 113 Instant Broadband ® Series 112 17. From the Rules tab, shown in Figure C-26, click the Closebutton to return tothe secpol screen. In the IP Security Policies on Local Computer window, shown in Figure C-27, right-click the poli...
Page 61 - Select IP Addr. from the pull-down menu beside Remote Security; enter the default password admin. Press the Enter key.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 115 Instant Broadband ® Series 114 8. Select IP Addr. from the pull-down menu beside Remote Security Gateway. This would be the IP Address of your Internet connection as seenfrom the Internet. Enter this IP Address here. 9. Select...
Page 62 - Appendix D: SNMP Functions
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 117 Instant Broadband ® Series Appendix D: SNMP Functions SNMP (Simple Network Management Protocol) is a widely-used networkmonitoring and control protocol. Data is passed from a SNMP agent, such asthe EtherFast Cable/DSL Firewall...
Page 63 - Write down the web address returned by the ping command (In the; Power on the computer and the cable or DSL modem, and restore the; Write down the IP address returned by the ping command. (In the
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 119 Instant Broadband ® Series 118 Step Two: Pinging for a Web Address While the IP address returned above would work as your e-mail server address,it may not be permanent. IP addresses change all the time. Web addresses, how-ever...
Page 64 - OK button. Windows may ask for original Windows installation; Protocol; Start button. Choose Settings and then Control Panel.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 6. Find and double-click TCP/IP in the list to the right (see Figure F-2). 7. After a few seconds, the main Network window will appear. The TCP/IP Protocol should now be listed. 8. Click the OK button. Windows may ask for original...
Page 65 - Start and Run. In the Open f ield, enter cmd. Press the Enter key; Appendix G: Finding the MAC; Start and Run. In the Open f ield, enter winipcfg. Then press the
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 3. Write down the Adapter Address as shown on your computer screen (see Figure G-3). This is the MAC address for your Ethernet adapter and willbe shown as a series of numbers and letters. The MAC address/Adapter Address is what yo...
Page 67 - Bridge - A device that interconnects different networks together.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint Cable Modem - A device that connects a computer to the cable television net-work, which in turn connects to the Internet. Once connected, cable modemusers have a continuous connection to the Internet. Cable modems featureasymmetri...
Page 69 - Hop - The link between two network nodes.
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint Hub - The device that serves as the central location for attaching wires fromworkstations. Can be passive, where there is no amplif ication of the signals; oractive, where the hubs are used like repeaters to provide an extension o...
Page 73 - Appendix I: Specifications; UTP Category 5 or Better; Environmental
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint 139 Appendix I: Specifications Model Number BEFSX41 Standards IEEE 802.3, IEEE 802.3u Protocol CSMA/CD Ports WAN: One 10/100 RJ-45 Port LAN: Four 10/100 RJ-45 Ports (One with DMZFunctionality) Cabling Type UTP Category 5 or Better...
Page 74 - Appendix K: Contact Information; Appendix J: Warranty Information
EtherFast ® Cable/DSL Firewall Router with 4-Port Switch/VPN Endpoint Appendix K: Contact Information For help with the installation or operation of the EtherFast Cable/DSL FirewallRouter, contact Linksys Technical Support at one of the phone numbers orInternet addresses below. Sales Information 800...